
The Central Bank of Libya acknowledged that data was allegedly published on the Dark Web following the June 9 incident but said its technical teams are still working to determine the scope of what was leaked. In a statement issued Saturday, the Central Bank of Libya said the data allegedly came from an earlier hacking operation rather than the most recent breach.
The bank emphasized that basic banking services, customer accounts, and the broader financial system remained stable and unaffected. It said no confirmed indications emerged during extensive assessments that accounts, balances, or financial assets had been breached, either for the bank itself or related banking organizations.
Social media reports have attributed the attack to the Qilin Group, a Russian-speaking cybercriminal organization known for using ransomware to encrypt targeted systems and demand payment for decryption or for agreeing not to publicly release stolen data. The Central Bank of Libya has not confirmed the identity of the attackers and has declined to discuss those claims publicly.
The bank said it rejected any negotiations or payments involving extortion and would not respond to demands that violate local legal and regulatory frameworks. Technical and criminal investigations are ongoing in coordination with local and international security institutions, the bank said.
The Central Bank of Libya said it is raising its cybersecurity level and implementing additional security measures as part of recovery efforts. The bank said it is working to ensure full system readiness and continued stability of banking operations and customer confidence.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543